Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2024-46048

    Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i... Read more

    Affected Products : fh451_firmware fh451
    • Published: Sep. 13, 2024
    • Modified: Sep. 20, 2024
  • 7.5

    HIGH
    CVE-2024-46047

    Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.... Read more

    Affected Products : fh451_firmware fh451
    • Published: Sep. 13, 2024
    • Modified: Sep. 20, 2024
  • 9.8

    CRITICAL
    CVE-2024-46046

    Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.... Read more

    Affected Products : fh451_firmware fh451
    • Published: Sep. 13, 2024
    • Modified: Sep. 20, 2024
  • 9.8

    CRITICAL
    CVE-2024-46044

    CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.... Read more

    Affected Products : ch22_firmware ch22
    • Published: Sep. 13, 2024
    • Modified: Sep. 20, 2024
  • 5.9

    MEDIUM
    CVE-2024-45040

    gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as implemented break the zero-knowledge property. The vulnerability affects only Groth16 proofs with com... Read more

    Affected Products : gnark-crypto gnark
    • Published: Sep. 06, 2024
    • Modified: Sep. 20, 2024
  • 6.2

    MEDIUM
    CVE-2024-45039

    gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case of multiple commitments used inside the circuit the prover is able to choose all but the last commitment. As gnark ... Read more

    Affected Products : gnark-crypto gnark
    • Published: Sep. 06, 2024
    • Modified: Sep. 20, 2024
  • 8.8

    HIGH
    CVE-2024-7717

    The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t... Read more

    Affected Products : wp_events_manager
    • Published: Aug. 31, 2024
    • Modified: Sep. 20, 2024
  • 5.3

    MEDIUM
    CVE-2022-4100

    The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly checking for a visitor's IP address. This makes it possible for an attacker whose IP address has been block... Read more

    • Published: Aug. 31, 2024
    • Modified: Sep. 20, 2024
  • 5.3

    MEDIUM
    CVE-2022-4536

    The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restr... Read more

    Affected Products : ip-vault-wp-firewall
    • Published: Aug. 31, 2024
    • Modified: Sep. 20, 2024
  • 7.8

    HIGH
    CVE-2024-38210

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more

    Affected Products : edge_chromium
    • Published: Aug. 22, 2024
    • Modified: Sep. 19, 2024
  • 7.8

    HIGH
    CVE-2024-38209

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more

    Affected Products : edge_chromium
    • Published: Aug. 22, 2024
    • Modified: Sep. 19, 2024
  • 6.1

    MEDIUM
    CVE-2024-38208

    Microsoft Edge for Android Spoofing Vulnerability... Read more

    Affected Products : android edge edge_chromium
    • Published: Aug. 22, 2024
    • Modified: Sep. 19, 2024
  • 6.3

    MEDIUM
    CVE-2024-38207

    Microsoft Edge (HTML-based) Memory Corruption Vulnerability... Read more

    Affected Products : edge_chromium
    • Published: Aug. 23, 2024
    • Modified: Sep. 19, 2024
  • 6.4

    MEDIUM
    CVE-2024-1384

    The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aux_recent_portfolios_grid' shortcode in all versions up to, and including, 2.3.3 due to insufficient input sanitization and... Read more

    Affected Products : auxinportfolio
    • Published: Aug. 29, 2024
    • Modified: Sep. 19, 2024
  • 7.5

    HIGH
    CVE-2024-3679

    The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.001. This makes it possible for unauthenticated attackers to view limited information from password protect... Read more

    Affected Products : wp_seo_plugin
    • Published: Aug. 29, 2024
    • Modified: Sep. 19, 2024
  • 6.4

    MEDIUM
    CVE-2024-1056

    The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe_tag_in_post' function which uses the 'wp_kses_allowed_html' filter to globally allow script and iframe tags in posts in all versions u... Read more

    Affected Products : funnel_builder
    • Published: Aug. 29, 2024
    • Modified: Sep. 19, 2024
  • 9.8

    CRITICAL
    CVE-2024-8302

    A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax/chpwd.php. The manipulation of the argument username leads to ... Read more

    Affected Products : dingfanzu dingfanzu
    • Published: Aug. 29, 2024
    • Modified: Sep. 19, 2024
  • 9.8

    CRITICAL
    CVE-2024-43144

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.... Read more

    Affected Products : cost_calculator_builder
    • Published: Aug. 29, 2024
    • Modified: Sep. 19, 2024
  • 9.8

    CRITICAL
    CVE-2024-43917

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.... Read more

    Affected Products : ti_woocommerce_wishlist
    • Published: Aug. 29, 2024
    • Modified: Sep. 19, 2024
  • 9.8

    CRITICAL
    CVE-2024-43922

    Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.... Read more

    Affected Products : nitropack
    • Published: Aug. 29, 2024
    • Modified: Sep. 19, 2024
Showing 20 of 290992 Results